Talya Medical تاليا الطبي
ع Request a Demo
ClinicSys

Privacy Policy

This policy states exactly what data the ClinicSys app processes, why, who it is shared with — and what we never do. It is written to match the app’s actual behaviour, not to fill a store field.

Last updated: 16 August 2026

1. Scope of this policy

This policy covers the ClinicSys app published by Talya Medical, bundle identifier com.talyamedical.clinicsys, on Android, iOS, desktop and the web edition.

ClinicSys is business software (B2B) licensed to clinics and medical centers under an agreement in the facility’s name. It is not sold to individual consumers or for family use, and it contains no in-app purchases.

2. Who owns the data?

The clinic is the Data Controller for everything concerning its patients. Talya Medical is a Data Processor that runs and hosts the system on the clinic’s instructions and within the limits of its contract.

Each clinic runs on its own isolated tenant, separated from every other clinic’s data. We do not review patient data or use it for any purpose of our own, and we access it only at the clinic’s explicit request for technical support.

If you are a patient of a clinic that uses ClinicSys and want to access, correct or delete your data, your point of contact is the clinic itself — we have no authority to act on a clinic’s patient data without its instructions.

3. Data the app processes

  • Account data: username, password stored hashed (never as plain text), role (owner, doctor, secretary, nurse, lab technician), and clinic name.
  • Trial workspace data: clinic name and a business phone number. No payment details or card data are requested at any stage.
  • Device binding data: the activation code and a device identifier, used to bind the device to your clinic and enforce the clinic’s device limit.
  • Notification token: a Firebase Cloud Messaging device token, used to deliver your clinic’s notifications and system announcements.
  • Clinic operational data: patient files, vitals, diagnoses, appointments, visits, invoices and attachments — entered by the clinic and stored on its own tenant.
  • Technical logs: request time and server response code, kept for a limited period for security and service stability.

4. What we do not collect or do

These are not general promises — the app is free of these components at the code level:

  • We use no behavioural analytics tooling inside the app.
  • We use no crash reporting tooling (Crashlytics or similar).
  • We do not track you across other apps or websites, and we use no advertising identifier.
  • We show no advertising whatsoever.
  • We do not sell your data, and we do not share it with data brokers or advertisers.
  • We do not request your location, your contacts, or your photos.
  • The app contains no in-app purchase and no external purchase link.

5. Permissions and why we ask

  • Camera — to scan the QR code that activates the device for your clinic, and nothing else. No photo is captured, stored or transmitted anywhere, and you can type the activation code manually and skip the camera entirely.
  • Notifications — to deliver your clinic’s notifications and system announcements. You can decline or later disable this in your phone’s system settings, and the app keeps working fully.
  • Internet access — to communicate with your clinic’s server.

6. Who data is shared with

ClinicSys shares data only with the following parties, and only for the stated purposes:

  • Google Firebase Cloud Messaging — to deliver notifications to your device. It processes the device token only; no medical content or patient data passes through it.
  • Apple App Store and Google Play — to distribute and update the app; they process download and purchase data under their own policies.

No third party beyond these. Patient data is never shared with any advertising, analytics or commercial entity, under any circumstances.

7. Where data is stored and how it travels

  • Each clinic’s data is stored on a tenant dedicated to it on our managed servers, or on a server inside the clinic itself when the local-network (LAN) deployment option is used.
  • All traffic between the app and the server runs over encrypted HTTPS only.
  • Access tokens are kept on your device in the secure system store — Keychain on iOS and Keystore on Android — never in plain files.

8. Retention and deletion

Clinic data is retained for as long as the service agreement is active, or until the clinic asks for it to be deleted.

Deleting a personal account is immediate and erases the user’s identity completely, but it does not touch clinical records — those belong to the facility rather than the employee, and they stay attributed to a "deleted user" with no identifying data.

Deleting a clinic runs automatically after a 14-day grace period. It is a real delete from the database — not a deactivation or an archive — and it includes files and attachments stored on disk.

Both actions start and complete from inside the app, without contacting us and without our approval.

9. How data is protected

  • Complete isolation of each clinic’s data on its own tenant.
  • Granular roles and permissions, set by the clinic owner for each staff member.
  • Devices bound by an activation code with a device limit, and any device can be unbound immediately.
  • Passwords stored hashed with bcrypt, and all traffic fully encrypted.
  • A backup the clinic administrator creates on demand from inside the system, saved as a file belonging to the clinic.

ClinicSys runs no scheduled automatic backup — a backup starts when the clinic administrator asks for one. Any backup your clinic created before deleting its data stays in the clinic’s own hands, and destroying it is the clinic’s responsibility.

10. Children

ClinicSys is a professional tool for clinic staff. It is not directed at children and is not designed for their use. We do not create accounts for children or knowingly collect their data.

Data about minor patients that a clinic enters into its own medical records falls under the clinic’s responsibility as Data Controller and under its professional and legal obligations.

11. Your rights

System users (clinic staff) exercise these rights by contacting us directly. Patients should contact their clinic.

  • Request a copy of the data we process about you.
  • Request correction of inaccurate data.
  • Request deletion of your account, or of your clinic and all of its data.
  • Withdraw your consent to notifications at any time from your device settings.

12. Changes to this policy

We may update this policy as the app or regulatory requirements change. The last-updated date appears at the top of this page, and we notify contracted clinics of any material change before it takes effect.

13. Contact us

For any question about this policy, or to exercise any of your rights, contact us and we will respond promptly.

Talya Medical
+963 985 557 722Chat with us on WhatsApp